Answered: [Security threat] tags are not sanitized in extra question field

Post date: 2020-07-01 00:44:51
Views: 199

Hey q2apro, I think you are testing the default q_view_extra($q_view); function.

The default function is still safe. But if you pull the content from the databse, it's not safe.

First, look! The script is stored in database.

database

Second, if create a function to pull that content form the datase:

public function q_item_extra($q_item)
{
$postidz = $q_item'raw']'postid'];
$extra = qa_db_read_one_value(qa_db_query_sub(
       'SELECT content FROM ^postmetas WHERE title="qa_q_extra" AND postid=#',
        $postidz
   ), true);
 
 //$extra = $q_item'extra']'content'];
 
        $this->output('My info:'.$extra);   
   
}

Here's the result:

test

I hope you'll get my point.

Please click Here to read the full story.
 
Other Top and Latest Questions:
Delta CEO sees record earnings in reach again thanks to high-end travel demand
The top 10 jobs in the U.S. for 2026 all pay $100,000 or more, according to Indeed
Bank of America boosts Micron price target, sees upside driven by tight memory supply
JPMorgan Chase tops estimates as trading revenue exceeds expectations
Salesforce releases updated Slackbot powered by Anthropic's AI model
Goldman Sachs CEO is looking at how the Wall Street bank can get involved in prediction markets
Trump accepts Nobel medal from Venezuelan opposition leader Machado
Japan's Mitsubishi to acquire shale gas assets in U.S. for $7.5 billion
Stocks making the biggest moves premarket: PNC, ImmunityBio, Coupang & more
'Markets are callous': Why stocks aren't fazed by Iran, Greenland or Venezuela